SV-82347r1_rule
V-67857
SRG-APP-000141-DB-000093
SQL4-00-017200
CAT II
10
To disable the use of xp_cmdshell, from the query prompt:
EXEC sp_configure 'show advanced options', 1;
GO
RECONFIGURE;
GO
EXEC sp_configure 'xp_cmdshell', 0;
GO
RECONFIGURE;
GO
To determine if xp_cmdshell is enabled, execute the following commands:
EXEC SP_CONFIGURE 'show advanced options', '1';
RECONFIGURE WITH OVERRIDE;
EXEC SP_CONFIGURE 'xp_cmdshell';
If the value of config_value is 0, this is not a finding.
Review the system documentation to determine whether the use of xp_cmdshell is required and approved. If it is not approved, this is a finding.
V-67857
False
SQL4-00-017200
To determine if xp_cmdshell is enabled, execute the following commands:
EXEC SP_CONFIGURE 'show advanced options', '1';
RECONFIGURE WITH OVERRIDE;
EXEC SP_CONFIGURE 'xp_cmdshell';
If the value of config_value is 0, this is not a finding.
Review the system documentation to determine whether the use of xp_cmdshell is required and approved. If it is not approved, this is a finding.
M
2639